CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
5848 | CVE-2002-1464 | Candidate | Cross-site scripting (XSS) vulnerability in CafeLog b2 Weblog Tool allows remote attackers to insert arbitrary HTML or script via the GPC variable. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5849 | CVE-2002-1465 | Candidate | SQL injection vulnerability in CafeLog b2 Weblog Tool allows remote attackers to execute arbitrary SQL code via the tablehosts variable. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5854 | CVE-2002-1470 | Candidate | SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be logged in the world-readable sc_serv.log file. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5882 | CVE-2002-1498 | Candidate | Directory traversal vulnerability in SWServer 2.2 and earlier allows remote attackers to read arbitrary files via a URL containing .. sequences with "/" or "" characters. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View | |
5883 | CVE-2002-1499 | Candidate | Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actions via (1) the authornumber parameter in author.asp, (2) the discussblurbid parameter in discuss.asp, (3) the name parameter in holdcomment.asp, and (4) the email parameter in holdcomment.asp. | Proposed (20030317) | ACCEPT(1) Cole | NOOP(2) Cox, Wall | View |
Page 20288 of 20943, showing 5 records out of 104715 total, starting on record 101436, ending on 101440